CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-9850
6.4 MEDIUM

The Evenium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'evenium_single_event' shortcode in all versions up to, and including, 1.3.11 due …

Sep 11, 2025
CVE-2025-9693
8.0 HIGH

The User Meta – User Profile Builder and User management plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path …

Sep 11, 2025
CVE-2025-9635
4.3 MEDIUM

The Analytics Reduce Bounce Rate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.3. This is due …

Sep 11, 2025
CVE-2025-9634
4.3 MEDIUM

The Plugin updates blocker plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.2. This is due to …

Sep 11, 2025
CVE-2025-9633
4.3 MEDIUM

The LH Signing plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.83. This is due to missing …

Sep 11, 2025
CVE-2025-9632
4.3 MEDIUM

The PhpList Subber plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. This is due to missing …

Sep 11, 2025
CVE-2025-9631
4.3 MEDIUM

The AutoCatSet plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.4. This is due to missing or …

Sep 11, 2025
CVE-2025-9628
4.3 MEDIUM

The The integration of the AMO.CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is …

Sep 11, 2025
CVE-2025-9627
4.3 MEDIUM

The Run Log plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.10. This is due to missing …

Sep 11, 2025
CVE-2025-9623
4.3 MEDIUM

The Admin in English with Switch plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. This is …

Sep 11, 2025
CVE-2025-9620
6.1 MEDIUM

The Seo Monster plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.3.3. This is due to missing …

Sep 11, 2025
CVE-2025-9617
5.3 MEDIUM

The Publish approval plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. This is due to missing …

Sep 11, 2025
CVE-2025-9451
6.5 MEDIUM

The Smartcat Translator for WPML plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, …

Sep 11, 2025
CVE-2025-9128
6.4 MEDIUM

The eID Easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 4.9.3 due …

Sep 11, 2025
CVE-2025-9123
6.4 MEDIUM

The CBX Map for Google Map & OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the popup heading and location address parameters …

Sep 11, 2025
CVE-2025-9073
7.5 HIGH

The All in one Minifier plugin for WordPress is vulnerable to SQL Injection via the 'post_id' parameter in all versions up to, and including, 3.2 …

Sep 11, 2025
CVE-2025-8721
6.4 MEDIUM

The Workable Api plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's workable_jobs shortcode in all versions up to, and including, 1.0.4 …

Sep 11, 2025
CVE-2025-8692
4.9 MEDIUM

The Coupon API plugin for WordPress is vulnerable to SQL Injection via the ‘log_duration’ parameter in all versions up to, and including, 6.2.12 due to …

Sep 11, 2025
CVE-2025-8691
6.4 MEDIUM

The WP Scriptcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' parameter in all versions up to, and including, 2.0.0 due …

Sep 11, 2025
CVE-2025-8689
6.4 MEDIUM

The Elements Plus! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Comparison, HotSpot Plus, and Google Maps widgets in all …

Sep 11, 2025
CVE-2025-8686
6.4 MEDIUM

The WP Easy FAQs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's WP_EASY_FAQ shortcode in all versions up to, and including, …

Sep 11, 2025
CVE-2025-8570
9.8 CRITICAL

The BeyondCart Connector plugin for WordPress is vulnerable to Privilege Escalation due to improper JWT secret management and authorization within the determine_current_user filter in versions …

Sep 11, 2025
CVE-2025-8492
5.3 MEDIUM

The Salon Booking System, Appointment Scheduling for Salons, Spas & Small Businesses plugin for WordPress is vulnerable to unauthorized modification of data due to a …

Sep 11, 2025
CVE-2025-8481
4.3 MEDIUM

The Blog Designer For Elementor – Post Slider, Post Carousel, Post Grid plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.1.7. This …

Sep 11, 2025
CVE-2025-8445
6.4 MEDIUM

The Countdown Timer for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'countdown_label' Parameter in all versions up to, and including, …

Sep 11, 2025
CVE-2025-8425
8.8 HIGH

The My WP Translate plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability …

Sep 11, 2025
CVE-2025-8423
5.4 MEDIUM

The My WP Translate plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the mtswpt_remove_plugin() and ajax_update_export_code() …

Sep 11, 2025
CVE-2025-8422
7.5 HIGH

The Propovoice: All-in-One Client Management System plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 1.7.6.7 via the …

Sep 11, 2025
CVE-2025-8417
8.1 HIGH

The Catalog Importer, Scraper & Crawler plugin for WordPress is vulnerable to PHP code injection in all versions up to, and including, 5.1.4. This is …

Sep 11, 2025
CVE-2025-8398
6.4 MEDIUM

The azurecurve BBCode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'url' shortcode in all versions up to, and including, 2.0.4 …

Sep 11, 2025
CVE-2025-8392
6.4 MEDIUM

The Mitfahrgelegenheit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘date’ parameter in all versions up to, and including, 1.1.5 due to …

Sep 11, 2025
CVE-2025-8318
6.4 MEDIUM

The Jobify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘keyword’ parameter in all versions up to, and including, 1.4.4 due to …

Sep 11, 2025
CVE-2025-8316
6.4 MEDIUM

The Certifica WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘evento’ parameter in all versions up to, and including, 3.1 due …

Sep 11, 2025
CVE-2025-8215
6.4 MEDIUM

The Responsive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 2.0.1 …

Sep 11, 2025
CVE-2025-5801
6.4 MEDIUM

The Digital Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘column’ parameter in all versions up to, and including, 1.0.8 …

Sep 11, 2025
CVE-2025-0763
4.3 MEDIUM

The Ultimate Classified Listings plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_custom_fields function in …

Sep 11, 2025
CVE-2025-8479
4.3 MEDIUM

The Zoho Flow plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.14.1. This is due to missing or …

Sep 11, 2025
CVE-2025-9059

The Altiris Core Agent Updater package (AeXNSC.exe) is prone to an elevation of privileges vulnerability through DLL hijacking.

Sep 11, 2025
CVE-2025-9034
6.1 MEDIUM

The Wp Edit Password Protected WordPress plugin before 1.3.5 does not validate a parameter before redirecting the user to its value, leading to an Open …

Sep 11, 2025
CVE-2025-10247
6.3 MEDIUM

A security vulnerability has been detected in JEPaaS 7.2.8. This vulnerability affects the function doFilterInternal of the component Filter Handler. Such manipulation leads to improper …

Sep 11, 2025
CVE-2025-9910
4.7 MEDIUM

Versions of the package jsondiffpatch before 0.7.2 are vulnerable to Cross-site Scripting (XSS) via HtmlFormatter::nodeBegin. An attacker can inject malicious scripts into HTML payloads that …

Sep 11, 2025
CVE-2025-9776
6.5 MEDIUM

The CatFolders – Tame Your WordPress Media Library by Category plugin for WordPress is vulnerable to time-based SQL Injection via the CSV Import contents in …

Sep 11, 2025
CVE-2025-10246
3.5 LOW

A weakness has been identified in lokibhardwaj PHP-Code-For-Unlimited-File-Upload up to 124fe96324915490c81eaf7db3234b0b4e4bab3c. This affects an unknown part of the file /f.php. This manipulation of the argument …

Sep 11, 2025
CVE-2025-10245
4.3 MEDIUM

A security flaw has been discovered in Display Painéis TGA up to 7.1.41. Affected by this issue is some unknown functionality of the file /gallery/rename …

Sep 11, 2025
CVE-2025-10236
4.3 MEDIUM

A vulnerability has been found in binary-husky gpt_academic up to 3.91. Impacted is the function merge_tex_files_ of the file crazy_functions/latex_fns/latex_toolbox.py of the component LaTeX File …

Sep 11, 2025
CVE-2025-6088
3.1 LOW

In version 0.7.8 of danny-avila/librechat, improper authorization controls in the conversation sharing feature allow unauthorized access to other users' conversations if the conversation ID is …

Sep 11, 2025
CVE-2025-10235
2.4 LOW

A flaw has been found in Scada-LTS up to 2.7.8.1. This issue affects some unknown processing of the file /reports.shtm of the component Reports Module. …

Sep 11, 2025
CVE-2025-10234
2.4 LOW

A vulnerability was detected in Scada-LTS up to 2.7.8.1. This vulnerability affects unknown code of the file /data_point_edit.shtm of the component Data Point Edit Module. …

Sep 11, 2025
CVE-2025-10233
6.3 MEDIUM

A security vulnerability has been detected in kalcaddle kodbox 1.61. This affects the function fileGet/fileSave of the file app/controller/explorer/editor.class.php. The manipulation of the argument path …

Sep 10, 2025
CVE-2025-10232
5.4 MEDIUM

A weakness has been identified in 299ko up to 2.0.0. Affected by this issue is the function getSentDir/delete of the file plugin/filemanager/controllers/FileManagerAPIController.php. Executing manipulation can …

Sep 10, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.